Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

21–30 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#22

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.

Well, we should move to multi-party computation when you can distribute secrets between different devices with redundancy and security.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#23

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

Take a photo with a second phone/webcam?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#24

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.

I think that’s the point, and why “very secure” is quoted.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#25
post #21

TOTP is bad 2FA. Google supports U2F security keys. Use them.

If you lose your U2F security key, are you sure you'll be able to remove it from your Google account? Because what I'm experiencing right now is that they support TOTP and you can't remove it if you lose it..

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#26
Oh my god. 2-Step verification on your Google Account is actually less secure than not using it at all.

I just posted about something similar maybe 3 months ago?[1]

> I kid you not. Google's actual official answer to this is... create another account![1][2][3]

> Edit: Now that I have your attention:

> PSA: Go create "Backup codes" for your Google Account in your 2-Step Verification settings.

> [1]: https://support.google.com/accounts/troubleshooter/2402620?h...

> [2]: https://support.google.com/accounts/answer/7682439

> [3]: https://support.google.com/accounts/answer/7299973

[1]: https://news.ycombinator.com/item?id=33692942

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#29

Oh my god. 2-Step verification on your Google Account is actually less secure than not using it at all. I just posted about something similar maybe 3 months ago?[1] > I kid you not. Google's actual official answer to this is... create another account![1][2][3] > Edit: Now that I have your attention: > PSA: Go create "Backup codes" for your Google Account in your 2-Step Verification settings. > [1]: https://support.go…

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account.

To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#30

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Good idea! That had never occurred to me before this incident.

Really? At what point do we blame the victim because this is so obvious to me.

I keep the TOTP and only sometimes keep the backup codes

I avoid the issue created from losing my phone, because the next device can generate codes immediately by importing or scanning the TOTP

I also don’t call it “2 factor” I just call it “one time passcode”

Post reply on HN